Being unique and immutable for each person, biometric signals are widely used in access control systems. While biometric recognition appeases concerns about password's theft or loss, at the same time it raises concerns about individual privacy. Central servers store several enrolled biometrics, hence security against theft must be provided during biometric transmission and against those who have access to the database. If a server's database is compromised, other systems using the same biometric templates could also be compromised as well. One solution is to encrypt the stored templates. Nonetheless, when using traditional cryptosystem, data must be decrypted before executing the protocol, leaving the database vulnerable. To overcame this problem and protect both the server and the client, biometrics should be processed while encrypted. This is possible by using secure two-party computation protocols, mainly based on Garbled Circuits (GC) and additive Homomorphic Encryption (HE). Both GC and HE based solutions are efficient yet interactive, meaning that the client takes part in the computation. Instead in this paper we propose a non-interactive protocol for privacy preserving biometric authentication based on a Somewhat Homomorphic Encryption (SHE) scheme, modified to handle integer values, and also suggest a blinding method to protect the system from spoofing attacks. Although our solution is not as efficient as the ones based on GC or HE, the protocol needs no interaction, moving the computation entirely on the server side and leaving only inputs encryption and outputs decryption to the client.

SHE based Non Interactive Privacy Preserving Biometric Authentication Protocols / Droandi, G; Lazzeretti, Riccardo. - (2015), pp. 1-6. (Intervento presentato al convegno 9th IEEE International Symposium on Intelligent Signal Processing, WISP 2015 tenutosi a Siena; Italy) [10.1109/WISP.2015.7139180].

SHE based Non Interactive Privacy Preserving Biometric Authentication Protocols

LAZZERETTI, RICCARDO
2015

Abstract

Being unique and immutable for each person, biometric signals are widely used in access control systems. While biometric recognition appeases concerns about password's theft or loss, at the same time it raises concerns about individual privacy. Central servers store several enrolled biometrics, hence security against theft must be provided during biometric transmission and against those who have access to the database. If a server's database is compromised, other systems using the same biometric templates could also be compromised as well. One solution is to encrypt the stored templates. Nonetheless, when using traditional cryptosystem, data must be decrypted before executing the protocol, leaving the database vulnerable. To overcame this problem and protect both the server and the client, biometrics should be processed while encrypted. This is possible by using secure two-party computation protocols, mainly based on Garbled Circuits (GC) and additive Homomorphic Encryption (HE). Both GC and HE based solutions are efficient yet interactive, meaning that the client takes part in the computation. Instead in this paper we propose a non-interactive protocol for privacy preserving biometric authentication based on a Somewhat Homomorphic Encryption (SHE) scheme, modified to handle integer values, and also suggest a blinding method to protect the system from spoofing attacks. Although our solution is not as efficient as the ones based on GC or HE, the protocol needs no interaction, moving the computation entirely on the server side and leaving only inputs encryption and outputs decryption to the client.
2015
9th IEEE International Symposium on Intelligent Signal Processing, WISP 2015
Signal Processing in the encrypted domain; Somewhat homomorphic encryption; biometric protection
04 Pubblicazione in atti di convegno::04b Atto di convegno in volume
SHE based Non Interactive Privacy Preserving Biometric Authentication Protocols / Droandi, G; Lazzeretti, Riccardo. - (2015), pp. 1-6. (Intervento presentato al convegno 9th IEEE International Symposium on Intelligent Signal Processing, WISP 2015 tenutosi a Siena; Italy) [10.1109/WISP.2015.7139180].
File allegati a questo prodotto
File Dimensione Formato  
Droandi_Postprint-SHE-based-non-interactive_2015.pdf

accesso aperto

Note: https://ieeexplore.ieee.org/document/7139180
Tipologia: Documento in Post-print (versione successiva alla peer review e accettata per la pubblicazione)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 320.3 kB
Formato Adobe PDF
320.3 kB Adobe PDF
Droandi_SHE-based-non-interactive_2015.pdf

solo gestori archivio

Tipologia: Versione editoriale (versione pubblicata con il layout dell'editore)
Licenza: Tutti i diritti riservati (All rights reserved)
Dimensione 858.74 kB
Formato Adobe PDF
858.74 kB Adobe PDF   Contatta l'autore

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11573/967180
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 1
  • ???jsp.display-item.citation.isi??? 0
social impact